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1.(1 INTRODUCTION 

1.1 Purpose 

This Interconnection Security Agreement (ISA) is required by Federal and Department of 
Homeland Security (DHS) policy and establishes individual and organizational security 
responsibilities lor protection and handling of DHS Scnsitive-bul-Unelassilied (SBUv lor 
Official Use Only (I'OUO) information. All specific requirements by both signatory 
organizations are also included in this ISA. 

1.2 References 

The authority for interconnect) vity between information systems is based on the follow ing 
federal guidance: Homeland Security Presidential Decision Directive 7; applicable National 
Institute of Standards and Technology (NIST) guidance (i.e., NIST Special Publication 800-47, 
Security Guide for Interconnection Information 'Technology Systems)’, Office of Management and 


1.0 INTRODUCTION 


1.1 Purpose 

This Interconnection Security Agreement (ISA) is required by Federal and Department of 
Homeland Security (DHS) policy and establishes individual and organizational security 
responsibilities for protection and handling of DHS Scnsili vc-but-Unclassi fi cd (SBU)/ For 
Official Use Only (FOUO) information. All specific requirements by both signatory 
organizations are also included in this ISA. 

1.2 References 

The authority for interconnectivity between information systems is based on the following 
federal guidance: Homeland Security Presidential Decision Directive 7; applicable National 
Institute of Standards and Technology (NIST) guidance (i.e,. NIST Special Publication 800-47. 
Security Guide jar Interconnection information Technology Systems): Office of Management and 
Budget Circular A- 1 30. Management of Federal Information Systems, Appendix 111. Security of 
Federal Automated Information Resources ; applicable Immigration and Customs enforcement 
(ICE) Information Assurance Division (IAD) guidance documents: DHS Information Technology 
(IT) Security Publication 4300A, DflS Sensitive Systems Policy Publication. D1 IS Management 
Directive 1 1042. Safeguarding SBU/FOUO Information ; and other applicable DHS direction. 

1 .3 Scope 

A T1 circuit will be used to access DHS and the Federal Bureau of Investigations (FBI) systems 
{Enforcement Case Tracking System ( E N FORC F )/A utomated Biometric Identification System 
{ID ENT), and Integrated Automated Fingerprint Identification System (I APIS), and 
HTTP/HTTPS. 'Exchange (DHS Intranet Web Portals). Central Index System (CIS), Computer 
linked Application! Information Management System (CLAIMS), Deport able Alicnt Control 
System (DAOS), National File Tracking System (NT ! S), and National Security Entry'Exit 
Registration System (NSEERS) to support the delegation of authority to the Washington 
County Sheriff Office (WCSO). Two data terminals will be connected to this circuit. This is 
a new installation, and no previous data access has been at this site. This is not an ICE 
controlled facility, but rather a county jail facility in Fayetteville, Arkansas. This 
delegation of authority pro ject has been approved by Assistant Secretary Clark on or around 
December 1 1 . 2005. 


1.4 Points of Contact 


The established points of contact (POC) for all issues associated with this agreement are 
available in Exhibit 1 : 


Exhibit 1 : Points of Contact 


1CF. Technical Point of ( ontact (TPOC) 


287(g) TPOC 


! Name: I (b)(6), (b)(7)c | 

Phone: (202) 380 (b)(6), (b) (7)c 
| Fax: (504) 589 [b)(6), (b)(7)j 

j E-mail: J 

| Name: | (b)(6), (b)(7)c ] 

j Phone: (479) 4 44-| (b)(6), (b) (7)c | 
j Fax: (479) 444 fb)(6), (b)(7)cj 
E-mail: 


DIIS ICE Office of Investigation Special Agent 
in Charge sponsor 



2.0 INTERCONNECTION STATEMENT OF AGREEM ENT 

The intent of this ISA is to provide DHS ICE agents, contractors, and WCSO with exclusive ICE 
access to those systems listed in Exhibit 2. This ISA encompasses the connection of the DHS 
wide area network via a T 1 to the Joint Enforcement Operations Facility located at the WCSO 

1155 Clydesdale Drive, Fayetteville, Arkansas 72701. Personnel will ut ilize these systems 

to process aliens and conduct investigations. 

The access to DHS and FBI systems (refer to Exhibit 2) from WCSO will be a network 
connection between the DHS Wide Area Network (WAN) and the ICE DHS local area network 
(LAN), which consists of T1 network connection via DHS ICE. 

ICE-provided equipment is owned by DHS and WCSO has the responsibility to secure the 
location of the equipment. Both organizations are authorized to perform on-site verification to 
the extent necessary to confirm compliance with this agreement. 



2.1 WCSO LAN Staff Responsibilities 

ThcWCSO LAN staff responsibilities include: 

• Limiting workstation logon access only to cleared and authorized users of specific DHS and 
FBI, 

2.2 ICE Office of the Chief Information Infrastructure Engineering Staff 
Responsibilities 

ICE Infrastructure Engineering Staff responsibilities include: 

• Setting up User accounts to support 287(g) activities 

• Providing a user group Internet Protocol (IP) list (and updates) to the DHS ICE Infrastructure 
Engineering Firewall Staff 

• Enabling stringent Identification and Authorization enforcement, using DHS 

Pass' word/ system inactivity standards (e.g., Windows password protected screen saver) as 
described in Section 3.7 

• Establishing of end-to-end session and login encryption between each workstation and the 
DHS firewall. 

• Utilizing the ICE image which includes hardened operating system, rigorous patch/Serviee 
Patch, and anti-virus management 

The approval of this ISA does not include the ability for outside agency to establish user 
accounts. DHS ICE security policies and procedures must be followed for clearances and written 
authorization by DHS. 

System administration and maintenance of ICE-owned networking devices and workstations are 
the sole responsibility of the ICE OCIO staff, including the Firewall Staff, Enterprise Operations 
Center (EOC) (routers and switches), and others as necessary and appropriate. 


Auditing of user connectiv ity through the firewall and Internet brow sing via the DHS portal will 
be performed in accordance with DHS policies and procedures. 

Exhibit 2: Systems/Applications to Access 


Acronym 

System 

1DENT 

Automated Biometric Identification System 

ENFORCE 

Enforcement Case Tracking System 

I APIS 

Integrated Automated Fingerprint Identification System 

HTTP/HTTPS I xchange 

DHS Intranet Web Portals 

CIS 

| ( ’entral Index System 

CLAIMS 

Computer Linked Application Information Management System 
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H I- Hi 


Acronym 



System 



NS FERN 




Deportable Alien Control System 

National hk I racking S : ,*m 

National Security RnlryExu Registration System 
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3.0 SYSTEM SECURITY CONSIDERATIONS 

3.1 Formal Security Policy 

All other government agencies (OGAl, contractors, and DHS must comply with existing Federal 
security and privacy laws and regulations in order to protect Federal systems and data. 
Additionally, ICE in the protection of DUS systems and data, will utilize DUS and ICE IAD 
documents, listed in section 1 .2. OGAs and contractors shall comply with their own internal 
agency security policies as well as the higher-level requirements applicable to their operations. 
Additionally, OGAs and contractors agree .to requirements set forth by ICE. Circuits associated 
with this ISA are required by DHS 4300A to enforce and maintain FIPS 140-2 level encryption 

3.2 General Information/Data Description 

The biometric data of IAF1S will transport through the Criminal Justice Information System 
(CJIS > Gateway-CJIS WAN. This data will include fingerprint image data. The interconnection 
will utilize FIPS 140-2 compliant encryption technologies provided through Transport Level 
Security (TLS) 1 .0. Biographic, biometric (in the form often fingerprints), and search result data 
will he transmitted to 1DENT. Illegal or criminal aliens encountered by OGAs will be checked 
against DUS records and processed for removal from the U.S. or prosecuted in ITS. District 
Court, as appropriate. 

3.3 Services Offered 

The client workstation will utilize Transmission Control Protocol (TCPklnternet Piotocol (IP) 
for accessing systems. The systems are identified in Exhibit 2. 

Technical detail is provided in the high-level illustration in Exhibit 3 and the business case 
requirements table maintained by the lAD staff. 

3.4 Data Sensitivity 

The data passed to the 287(g) agents, via the DHS WAN connection, will be considered 
SBU/FOUO sensitivity level 2. 

3.5 User Community 

The user community will be restricted to staff having an appropriate background investigation, 
and authorized by the ICE PQC, based on DHS 4300A. By DHS Sensitive Systems Policy, non- 
DHS staff is permitted "read/ write” access to DHS and FBI systems. DI IS 4300 A security policy 
4.1.1c slates that. "Only U.S. citizens shall be granted access to DHS systems processing 
sensitive information. An exception to the U.S. citizenship requirement may be granted by the 
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Component Head or designee with the concurrence of the Office ofSeeurity and the OHS CIO or 
their designees." 

3.6 Information Exchange Security 

The information accessed by the 287(g) site shall be considered sensitivity level is 2. The 
information must be protected in accordance with DHS 4300A Sensitive Systems Policy and 
marked, stored, and disposed of in accordance with DHS MD 1 1042.1. 

3.7 DHS Rules of Behavior 

Each connected workstation will use and maintain the latest ICE-approvcd hard disk image/ 
configuration in compliance with DHS ICE 4300A Sensitive System Policy Rules of Behavior. 

Each agency shall protect the information shared under this agreement. Each agency shall 
implement the following security controls; 

a) Anti-Virus Workstations will include the ICE-approved anti-virus software with current 

definitions. 

h) Clearance DHS will restrict system access to authorized DHS ICE Special Agents or 
employees and 287(g) personnel who must be U.S. citizens with favorable background 
investigations who require this information in the course of official DHS ICE duties. 

c) Data Storage 287(g) personnel are not permitted to replicate or store any system 
information in a separate database or in any other electronic format, unless approved by the 
system owner. 

d) Disabled Sessions Workstations shall be configured to automatically disable inactive 

sessions after no more than 20 minutes of inactivity. Authentication must be required to re- 
establish the session, either through unlocking a screensaver or logging onto the workstation. 

e) Passwords All 287(g) personnel are to go to the 287(g) Project Management Officer at 
your site. The Officer will set up the process for 287(g) training including acquiring User IDs 
and passwords. For subsequent password changes during the course of the year, 287(g) 
personnel should go to the local Password and Issuance and Control System (PICS) officer at 
the Special Agent in Charge (SAC) office or at the Detention and Remov al Office's Field 
Office Director (FOD). The 287(g) TPOC must also submit password changes to the ICE 
Help Desk at 1-888-347-7762 or via the Internet at http;//rcniedyvveb. ice.dhs.gov/help. 

287(g) users must utilize the following policy for passw ords. Passwords must: 

- Be at least eight characters in length 

- Contain a combination of alphabetic, numeric, special characters and not contain any 
dictionary word, e.i. (!:Vf ••$%) 

- Contain no more than two identical consecutive characters in any position from previous 
password 

- Not be the same as the previous eight passwords 

- Contain a combination of upper and lower case alphabetic letters 


n,i 


- Not be shared among users under any circumstances (including DHS ICE, VVCSO and 
11011 -ICE personnel) 

All 287(g) personnel accessing data must complete a DHS/ICE 287(g) Access Request Form 
covering each system. The 287(g) users then must submit the 287(g) Access Request Form to 
the local PICS Officer at the SAC or FOD. I (possible, please hand deliver the completed 287(g) 
Access Request Form to the local PICS Officer. If it must be sent via e-mail, please note the 
following: Due to the inclusion of Social Security Number information on the 287(g) Access 
Request Form, this form must be compressed and encrypted using WinZip or cquix alent software 
and then emailed. The password for this form must be delivered in a separate email. 
Coordination of fax transfer should be made prior to that transfer. 

f) Printing Any output of 287(g) information to media other than the screen is prohibited. 

g) Privacy In accordance with Federal Information Processing Standards. 287(g) may not 
disclose information obtained from the system to a third party, without written permission 
from ICE. Personally Identifiable Information (I’ll) must be controlled and safeguarded 
according to federal guidelines. This data is to only be used for those having an authorized 
purpose only and must be destroyed after 90 days. 

h) System Modifications System access from the facility is read 'write unless approx ed in 
writing by the Information System Security Officer. 

3.8 Incident Reporting 

Any information regarding security incidents as defined by DHS and ICE security policies in 
references listed in Section 1 .2 will be reported to the ICE 1 lelp Desk at (888) 347-7762. 

3.9 Audit Trail Responsibilities 

Auditing of the systems’ transactions will be the responsibility of DHS ’FBl system owners. 

3.10 Security Parameters 

DHS ICE has the responsibility to protect against possible intrusions to the ICE connections to 
the DHS WAN. 287(g) personnel will allow ICE to perform vulnerability assessments on this 
connection in order to verify established-continued access security as set forth by this ISA. 

3.1 1 Training and Awareness 

The DHS ICE Office of Investigation Special Agent in Charge sponsor shall ensure that DHS 
and 287(g) personnel, with access to DHS ICE systems, have documented participation in 
mandatory ICE Computer Security Awareness Training. These sessions shall be taken initially 
and annually. 

3.12 Specific Equipment Restrictions 

Government Furnished Equipment that are oil the 287(g) Network shall be configured and 
maintained to current ICE Image Lab standards. Special purpose circuits, routers, servers, and 
workstations will be configured and maintained in compliance with current, mandatory security 
polices. 
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All equipment with access to host 287(g) sites must be located in a secured area not accessible to 
the public and must be restricted to cleared and authorized staff. 

3.13 Dial-Up Connectivity 

N/a. 

3.14 Security Documentation 

ICE System Security Plans and other Certification and Accreditation documentation will be 
updated and provided to the ICE I AD as appropriate for systems accessed. 287(g) managerial and 
technical security policies and procedures may be requested and reviewed hy the DHS ICE PAD 
on a periodic basis. 

3.15 Site or System Certification and Accreditation 

This new connectivity between ICE and the non DEIS facility will be included in the System 
Interconnection/Information Sharing section of the DHS WAN System Security Plan during 
periodic updates. 
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4.0 TOPOLOGICAL DRAWING 

The network connectivity between the ICE and the WCSO is shown in Exhibit 3. 



Exhibit 3: iCE-to-WCSO Connectivity 


Center - 
MD 


MPLS (AES 128 Encryption) 
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5.0 SIGNATORY AUTHORITY 


Access from the ICE facility to required systems cannot occur until both signature authorities 
sign the ISA. 


The TSA is valid for 3 years after the last date oflatest signature below. This is considered a 
living document, to be reviewed annually and modified as circumstances warrant. This 
agreement may not be unilaterally modified and all changes to tire ISA must be reviewed and 
may necessitate a new ISA or an ISA Addendum. 


Luke McCormack T 
ICE Chief Information Officer 


' Chief Deputy | (b)(6), (b)(7)c 


Designated Accrediting Authority 


j Designated Accrediting Authority 


// - 9- cle x? ? 


(Signature and Date) 


(Signature and Date) 



ICE 1 AD 

WCSO DA A 

WCSO POO- 

ICE ISSO 

ENFORCE POC 

ID ENT POC 

LAPIS, NCIC, NI1S POC 

ICE OCIO 

ICE I AD 

ICE Infrastructure Engineering 
ICE Architecture 
ICE SOC Manager 
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Office of Investigations 


U.S. I)i'p;i rt mill of 1 Immlu nil SfCirrity 

One lower I.anc, Suite 1600 
Oakbrook Terrace. Illinois 601 8 i 



U.S. Immigration 
and Customs 
Enforcement 


December 14, 2007 


MEMORANDUM FOR: 


FROM: 


Marcy M. Forman 
Director 

Office of Investiga 


Special Agent in C 
Chicago, Illinois 


I (b)(6), (b)(7)c 


SUBJECT: Waukegan, Illinois Police Request for 287(g) Delegation of 

Authority Training 


U.S. Immigration and Customs Enforce 
Delegation of Authority training from| 


hved a request for 287(g) 
| for the Waukegan, 


Illinois Police Department, requesting /(g) Delegation of A uthority training for a minimum 
of two Waukegan Police Officers. In his 1 etter,D2jjjJSj2j||3 1 expres sed his desire to move 
forward with ICE in an effort to identify criminal aliens who pose a risk to the citizens of his 
community. ICE HQ requested that SAC Chicago initiate a field survey of the Waukegan 
Pol ice Department for consideration of acceptance into the 287(g) program. 


SAC Chi cago is curren tly available to support the Waukegan Police upon their receipt of 
training. £^£1311389 has requested 15 officers be trained in the program, but would be willing 
to fill up to 30 slots in a training class if it is held locally. Although two other departments in 
the Chicago metropolitan area are awaiting consideration for participation in the program, no 
other law enforcement agencies in the AOR are approved participants in the 287(g) program. 
Therefore, it is believe that SAC Chicago would he able to handle the increased workload 
should Waukegan be approved. However, if additional departments in the Chicago 
metropolitan area are approved for the 287(g) program, resource issues may have to be re- 
addressed to deal with the increased responsibilities. 


The Field Office Director has confirmed that the Waukegan Police Department is not a 
contract facility; however, DRO anticipates being able to handle the expected increase in aliens 
each month that Waukegan believes will be processed through the 287(g) program. 


/.ice. gov 



SUBJECT: Waukegan, Illinois Police Request for 287(g) Delegation of Authority Training 
Page 2 


Should the Assistant Secretary choose to approve or disapprove the request, the 287(g) 
Program Manager will draft a letter to the requesting agency with her response. 


Approved: 


Disapproved: 


Needs more discussion: 



Office of Investigations 

I'.S. Department of Homeland Securit 
425 I Street, NW 
Washington, DC 20536 



U.S. Immigration 
and Customs 
Enforcement 


I (b)(6), (b)(7)c 


420 Robert V. Sabonjian Place 
Waukegan. Illinois 6085 


Thank you for your interest in the 287(g) delegation of immigration authority program. The 
287(g) Program Management Office and the Office of the Assistant Secretary for U, S. 
Immigration and Customs Enforcement (ICE) are in receipt of your request for training for the 
Waukegan Police Department. 


On August 2, 2007, the Program Manager for 287(g) Delegation of Authority at ICE 
Headquarters forwarded your request to the Special Agent in Charge (SAC) Chicago. IL, and 
the Field Officer Director (FOD) of Detention and Removal, Chicago. Local representatives 
from these two divisions will be in contact with you soon to conduct a preliminary assessment 
and detennine whether the 287(g) program is the appropriate application to address your local 
law enforcement challenges. 


The local ICE point of contact regarding the 287(g) program is E 
who can be reached at 630-574-1 


Sincerely, 

Mi 

Roland Jcmes 

Acting State and Local Coordinator 

InvPdioafivp Qorvirps Division 




.S. Immigration 
hd Customs 
nforcement 


Program 

Information Officer 


IT Site Survey Report 


Washington County Sheriffs Office, AR 


FINAL 


Version 1.0 



Site Survey/Checklist 


Site Name: Washington County Sheriffs Office 
Survey Date: 04-17-07 

Assessment Conducted by: 

Riggs 

The main purpose of the document is to assist the survey team with assessing both the IT and Facility 
infrastructures. Within this document is a checklist of areas that need to be assessed including facility areas 
such as Physical access, HVAC, Electrical. IT areas will consist of cable plant, LAN and WAN components. 

Site Information 

Washington County Sheriffs Office 
1155 Clydesdale Drive 

Fayetteville, AR 72701 . . 

• Site POC: Major| (b)(6), (b)(7)c | Commander. (479M4 41 (b)(6), (b)(7 )c | 

• Site POC: [Sheriff's Deputy IT PO C (479)444 - | (b)(6), (b)(7)c~ 

• Site POC: (b)(6) ’ (b)(7)c Chief Deputy {Al§)44 $pm, (b)(7 )c | 


Official Site Code: 

Unofficial Site Code: 

ICE Team 

Jesus M. Garcia 
Jamie Wright 
Dale Riggs 

ISSUES 

The site is the Washington County Sheriffs Office and Detention Facility. It is located at 
1155 Clydesdale Drive, Fayetteville, Arkansas. This facility is fairly new and up to date 
with IT Technology. After touring the facility and looking at the number of detainees 
processed by the facility it was recommended that Washington County will be well served 
if they were to obtain two full IAFIS workstations : 

1. Interview Room in Processing/Holding Area, two (IAFIS) 


ITFO - 287G (956) 346 
ICE 287G (202)305-1 

Contractor (202) 2461 





The Interview Room designated to support two IAFIS workstation has no CAT 5 drops currently 
in place. The current plan is for the site to install all new CAT 5 cabling to connect the IAFIS 
workstations to the ICE Network via T1 connection. OCIO will add one twenty-four port switch 
to accommodate the two IAFIS Processing Workstations and provide flexibility for future 
expansion of the site. 

Equipment and Storage: 


Is there a loading dock to load /unload equipment 

If no, how the equipment can be delivered to the site? 

Equipment will be delivered to the intake area door 

Are there freight elevators at the site? 

If no, how will the equipment be distributed? 

Is there a pallet jack or another means for moving pallets? 

If no, what are the alternatives for moving pallets & boxes 
Hand delivery 

Is there are storage area available for boxes and pallets. 

If not is there an alternate off site storage location available? 

Equipment can be stored in the interview rooms. 

Is the physical security adequate for storage of (e.g., controlled building 
access, limited access to computer room, secure cabinets)? 

Are clearances required to gain access to the building 
What kind of badge is needed for access? By appointment 
Are the computer rooms locked or access controlled? 

Heating, Ventilation & Air Conditioning: 

Will the HVAC for the building shut down at a specified time? 

If yes, raise issue to local POC and OCIO management. 

Does the computer room have its own HVAC? 


YES □ NO IKI 


YES 

□ 

NO M 

YES 

□ 

NO IKI 

YES 

El 

NOD 

YES 

El' 

NOD 

YES 

E 

NO □ 

YES 

El” 

NOD 

YES 

□ 

noKI 

YES 

cf 

no El 


Electrical Power 


Site Name 

Server Room 

Is there 

dedicated 

power? 

If yes, how 
much 
dedicated 
power overall 
for server 
rooms? 

Is there room for 
expansion 

(i.e., addition of 
circuits)? 

#of 

circuits 

NOT in 
use today 

Is there 
dedicated 

UPS? 




(amps/watts) 








1 Electrical Outlets Required j 

Site Name 

Room / 

Location in 

Building 

(e.g., floor) 

Total # 
of 

Outlets 

Required 

N/A 

1. Washington 
County 

A. Interview 

Room 

4 



B. 

0 



Computer Room 

The computer room is located in located near the Investigations Office. It is secure, clean, 
and climate controlled. The walls are reinforced concrete and room complies with the 
local fire codes. 

There are no extenuating circumstances involving the site’s electrical power capabilities. 


Cable Plant Assessment 

Please provide the following: 


Is there an existing cable plant? 

YES IXI 

NO □ 

Are modifications required? 

YES IE 

NOD 

If so please describe and provide scheduled date of completion. The site 
wants to install all new CAT5. 



Have you attached all copper/fiber/MDF/RWC layouts available? 

YES □ 

NO IE 

Will there be sufficient rack space available in the Wiring Closet to add new 
equipment/ hardware? The site will install new rack for ICE equip. 

yesE 

NO □ 

Is there sufficient space in the Wiring Closet to add a cabinet or rack, if 
required? 

1 YES 0 

NO □ 

Is there adequate cooling in the Wiring Closet? 

; YESKI 

NOD 

Is there adequate power for the Wiring Closet? 

yesE 

NO □ 




Is the hardware in the Wiring Closet connected to a UPS? YES 


YESI3 NOD 


Data Communication Recommendations 


□ DSL WITH VPN 

□ County Owned T1 With VPN TOKEN 

Comments 

Comments 


I IEI ICE T1 

Comments 

ICE T-l is needed. 


Work Station Requests 

A total of two (2) IAFIS w orkstations were requested. The locations were agreed upon by 

The site will arrange to have the requisite CAT 5/6 cable run by local 
cabling company from the Demarc to the ICE Switch. The site will run all new CAT 5/6 cable from 
the Demarc to the IAFIS Workstations. 


Interview/Processing Area for all Inmates 

Two IAFIS workstations with a networked printer. The site will build out workspace to 
accommodate electrical and desktop needs to support the IAFIS workstation and all peripheral 
devices. 



IAFIS work area above 



Equipment required for locations pictured above: 


2 Workstations 
2 Ten Print Scanner 
2 Camera 
2 Flatbed Scanner 
2 Xerox Printers (Networked) 
2 HP 1320 Printers 


Telecom Room 




